system_server: replace sys_resource with sys_ptrace
Commit https://android.googlesource.com/kernel/common/+/f0ce0eee added
CAP_SYS_RESOURCE as a capability check which would allow access to
sensitive /proc/PID files. However, in an SELinux based world, allowing
this access causes CAP_SYS_RESOURCE to duplicate what CAP_SYS_PTRACE
(without :process ptrace) already provides.
Use CAP_SYS_PTRACE instead of CAP_SYS_RESOURCE.
Test: Device boots, functionality remains identical, no sys_resource
denials from system_server.
Bug 200288656
Bug 1940296
Bug: 34951864
Bug: 38496951
Change-Id: I04d745b436ad75ee1ebecf0a61c6891858022e34
(cherry picked from commit 448669540c0b7c22ee8b8293217818f8f92238b6)
(cherry picked from commit 3d8dde0e2e7ae6d6901ec3a708c8b891eacf1631)
Reviewed-on: https://git-master/r/1501479
Reviewed-by: Automatic_Commit_Validation_User
GVS: Gerrit_Virtual_Submit
Reviewed-by: Shawn Heo <sheo@nvidia.com>
Tested-by: Shawn Heo <sheo@nvidia.com>
Reviewed-by: Terrence Wu <terrencew@nvidia.com>
Tested-by: Terrence Wu <terrencew@nvidia.com>
Reviewed-on: https://git-master.nvidia.com/r/1544848
Reviewed-by: Eric Chuang <echuang@nvidia.com>
1 file changed